@verkflode/remit-core
v0.4.0
Published
Host-agnostic core of Remit: Allow/Ask/Never decision engine, job grants, decision records, drift detection, and calibration detectors for AI agent authority.
Readme
@verkflode/remit-core
The host-agnostic engine behind Remit: personal agent authority — owner-set Allow / Ask / Never tiers enforced at the tool-call layer, with every decision recorded.
This package is for adapter authors. It contains everything that is identical on every host:
- The twelve human categories and their conservative default tiers.
- The decision engine (
buildCatalog+createDecider): overrides > agent layers > categories, sensitive-target escalation, a read-only downgrade that can never soften a Never. - Job grants — owner-pre-authorized ask→allow batches with path fences and expiry — and their digests.
- Temporal caps (v0.4) — count / distinct-recipient / sum limits per category over rolling windows. A breached cap converts Allow to Ask, never blocks, and fails closed on gaps.
- The
vaom.decision/0.2record (request/resolution pair, digest-only — raw parameter values are never stored), the time-windowed JSONL decision store, config drift detection, and the calibration anti-pattern detectors. - A Dogwood event-trace exporter for offline replay (mapping).
A host adapter provides: a catalog of its real tool names, an interception seam, an approval transport, and state paths. See the seams contract in design 0002 and the two shipped adapters (OpenClaw, Claude Code) as references.
Zero runtime dependencies. The security pass is executable — src/security.test.ts fails the build on any outbound network call, environment read, spawned process, or salt leak.
MIT © Verkflöde
